CVE-2025-2526
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 8, 2025
CWE ID 639
Summary
CVE-2025-2526 is a privilege escalation vulnerability affecting the Streamit theme for WordPress. The issue arises from the theme's failure to verify user identities before updating their email addresses in the 'st_Authentication_Controller::edit_profile' function. As a result, unauthenticated attackers can manipulate email addresses for any user, including administrators, ultimately leading to account takeover. This allows attackers to reset passwords and gain administrator access, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.